PaperCut Ships Permanent Fixes After Weeks of Emergency Patching
PaperCut has released regular maintenance updates for PaperCut NG/MF that formally supersede a string of emergency patches issued over the prior weeks to address two actively exploited vulnerabilities. The company says the new releases "contain all of the security fixes issued in Emergency Patch Releases 1, 2 and 3, plus additional security hardening."
The Vulnerabilities
- CVE-2026-81578 — An authentication bypass affecting PaperCut NG/MF.
- CVE-2026-82078 — An arbitrary code execution flaw affecting PaperCut NG/MF.
Fixed versions are PaperCut NG/MF 26.0.5, 25.0.13, and 24.1.10. Organizations that applied the earlier emergency patches should still upgrade to these maintenance releases, since they roll in additional hardening beyond the original hotfixes.
An AI-Scaled Attack Campaign
A suspected Russian-speaking threat actor weaponized both flaws to compromise at least 395 organizations across 48 countries, with U.S. educational institutions bearing the brunt of the targeting. Notably, the campaign reportedly used hundreds of AI agents powered by OpenAI's Codex and DeepSeek models to automate exploitation at scale — a sign of how AI tooling is lowering the bar for running high-volume, multi-target intrusion campaigns.
Investigators traced campaign infrastructure to IP address 45.142.193[.]132. The operators notably avoided targeting organizations in Russia, China, Hong Kong, Thailand, Iran, and more than twenty other countries — a common pattern among threat actors seeking to avoid domestic law-enforcement attention.
Why Education Was Hit Hardest
PaperCut's print-management software is deeply embedded in school and university IT environments, often with broad network reach to manage print jobs across labs, libraries, and administrative offices. That footprint, combined with historically under-resourced K-12 and higher-ed security teams, makes the sector a recurring soft target whenever a PaperCut flaw surfaces — this is not the platform's first brush with mass exploitation.
Mitigation
- Upgrade to PaperCut NG/MF 26.0.5, 25.0.13, or 24.1.10 immediately, even if emergency patches were already applied
- Review logs for indicators of compromise dating back to August 27, 2026, when the original security advisory was issued
- Block known malicious infrastructure, including IP 45.142.193[.]132
- Restrict PaperCut admin interfaces to trusted internal networks rather than exposing them to the internet
- Educational institutions in particular should treat PaperCut patching as a priority given the scale of targeting observed in this campaign
Source: The Hacker News